Compliance decisions
Special-category data in AI prompts
Special-category data needs both an Article 6 lawful basis and an applicable Article 9 condition, alongside the other GDPR requirements. An approved AI account, a DPA or ordinary redaction does not supply those grounds. First ask whether the task needs the sensitive information at all.
For DPOs, HR privacy teams and security owners
A legitimate-interest argument alone does not resolve special-category processing.
Synthetic employee information and proposed tasks. No actual lawful basis, consent or legal approval is established.01
Recognise the sensitive category in context
Article 9 covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, certain biometric data, health, sex life or sexual orientation. Biometric data is included where it is processed for uniquely identifying a person; not every photograph is automatically in that category.
An ordinary workplace document can contain these details incidentally. A scheduling note may reveal treatment, a payroll attachment may reveal union membership and an accommodation request may include health information. Assess the information actually disclosed, including attachments and contextual clues, rather than relying only on the file’s title.
Source context: EU GDPR: Regulation (EU) 2016/679
02
Establish both layers before disclosure
Article 6 establishes the general lawful-processing basis. Article 9 generally prohibits special-category processing unless a specified condition applies. The relevant condition is additional to, not a substitute for, the general requirements. Record the particular purpose and why that condition fits.
Some conditions depend on Union or Member State law and safeguards. For example, the employment and social-protection condition has legal-authorisation and necessity requirements; the healthcare condition has further qualifications, including professional secrecy requirements where applicable. “For HR” or “for healthcare” is not a complete analysis.
Source context: EU GDPR: Regulation (EU) 2016/679
03
Remove the need before removing a name
If staff want help phrasing a general policy, an invented situation may be enough. A personalised diagnosis or union list may add no value to that wording task. Redesigning the input can avoid disclosing information that the external recipient does not need.
If the remaining text can still relate to an identifiable person, treat pseudonymisation as a safeguard rather than automatic anonymisation. “Employee A, our only night-shift supervisor” may remain identifiable to the recipient. Review the revised input and the recipient’s context before deciding what obligations remain.
Source context: EU GDPR: Regulation (EU) 2016/679
04
Check the service after the purpose
For a real-data task, identify the provider’s role, instructions, subprocessors, transfers, security and retention. Those contract and operational questions remain necessary even where a lawful basis and special-category condition have been identified. A service’s refusal to train on inputs does not settle all other processing.
Assess whether a DPIA is required, including where large-scale special-category processing is involved. Keep the AI-use decision separate from the organisation’s permission to hold the source record. A legitimate HR record can still be disclosed for a different, unjustified purpose if copied into an external tool.
Source context: EU GDPR: Regulation (EU) 2016/679
05
Turn the analysis into a staff instruction
A useful instruction says which data and task are permitted, in which service, under which conditions, and who handles an exception. It should help an employee act without interpreting legal categories from scratch. Keep detailed legal reasoning with the accountable privacy owner.
The fictional cases below illustrate questions and reduced-data alternatives. They do not select a lawful basis for a real employer. Use them to test whether the proposed instruction catches both explicit labels and contextual disclosure, and record any unresolved question before using real sensitive information.
Source context: EU GDPR: Regulation (EU) 2016/679
Put it into practice
Sensitive-data input decision map
Invented workplace tasks separate purpose, data category and the additional Article 9 question, with a distinct Article 10 example.
Synthetic employee information and proposed tasks. No actual lawful basis, consent or legal approval is established.
Need
Does the task require this personal detail?
Grounds
Article 6 basis and Article 9 condition
Safeguards
Recipient, contract, transfers and risk
Instruction
A scoped rule staff can follow
| Proposed input | Category and issue | Decision in the exercise |
|---|---|---|
| “Rewrite our generic sick-leave policy.” | A general policy can be discussed without anyone’s health record. | Use invented context; do not attach employee diagnoses. |
| “Explain this named employee’s diagnosis to their manager.” | Health data; purpose, necessity, recipients and Article 6/9 grounds require review. | Do not use the real record in this exercise; escalate the specific disclosure. |
| A named list of union subscriptions | Trade-union membership is special-category data. | Do not infer permission from payroll access; assess the particular purpose and legal condition. |
| Face images proposed for identity matching | Biometric processing for unique identification can bring Article 9 into scope. | Assess the actual processing and safeguards; a generic photo label is insufficient. |
| A report about a criminal conviction | Article 10 has separate conditions. | Route for the applicable criminal-offence-data review rather than assuming Article 9 alone resolves it. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
gdpr-sensitive-ai-input-map.mdInspect
# Sensitive-data input decision map
Synthetic employee information and proposed tasks. No actual lawful basis, consent or legal approval is established.
Invented workplace tasks separate purpose, data category and the additional Article 9 question, with a distinct Article 10 example.
| Proposed input | Category and issue | Decision in the exercise |
| --- | --- | --- |
| “Rewrite our generic sick-leave policy.” | A general policy can be discussed without anyone’s health record. | Use invented context; do not attach employee diagnoses. |
| “Explain this named employee’s diagnosis to their manager.” | Health data; purpose, necessity, recipients and Article 6/9 grounds require review. | Do not use the real record in this exercise; escalate the specific disclosure. |
| A named list of union subscriptions | Trade-union membership is special-category data. | Do not infer permission from payroll access; assess the particular purpose and legal condition. |
| Face images proposed for identity matching | Biometric processing for unique identification can bring Article 9 into scope. | Assess the actual processing and safeguards; a generic photo label is insufficient. |
| A report about a criminal conviction | Article 10 has separate conditions. | Route for the applicable criminal-offence-data review rather than assuming Article 9 alone resolves it. |
## Review steps
- Question the sensitive detail: Identify whether an invented example or general description achieves the purpose without the personal record.
- Record both legal layers: Document the Article 6 basis and applicable Article 9 condition, including relevant national-law requirements.
- Review the real destination: Assess role, instructions, transfers, retention, recipient access and the need for a DPIA.
## Safe comparison fixture
General version: “Suggest clear wording for a workplace policy explaining how employees can request an adjustment.”
Over-detailed synthetic version: “Taylor Example, our only night-shift supervisor, has the fictional condition Example Syndrome. Explain their adjustment request to the manager.”
Use invented material only. The second version illustrates contextual identifiability; it is not a real employee record or a finding that a particular legal condition applies.
## Source and scope
Guide: https://aona.ai/resources/guides/gdpr-special-category-data-ai-prompts/
Source check: 21 September 2026. General information; no professional approval or installed-product result is represented.
- EU GDPR: Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
Download gdpr-sensitive-ai-input-map.mdgdpr-sensitive-ai-input-map.csvInspect
Proposed input,Category and issue,Decision in the exercise
“Rewrite our generic sick-leave policy.”,A general policy can be discussed without anyone’s health record.,Use invented context; do not attach employee diagnoses.
“Explain this named employee’s diagnosis to their manager.”,"Health data; purpose, necessity, recipients and Article 6/9 grounds require review.",Do not use the real record in this exercise; escalate the specific disclosure.
A named list of union subscriptions,Trade-union membership is special-category data.,Do not infer permission from payroll access; assess the particular purpose and legal condition.
Face images proposed for identity matching,Biometric processing for unique identification can bring Article 9 into scope.,Assess the actual processing and safeguards; a generic photo label is insufficient.
A report about a criminal conviction,Article 10 has separate conditions.,Route for the applicable criminal-offence-data review rather than assuming Article 9 alone resolves it.
Download gdpr-sensitive-ai-input-map.csvBefore you proceed
Keep these distinctions clear
- Legitimate interests is not an Article 9 condition
- Complete the additional special-category analysis rather than stopping at Article 6.
- A pseudonym can remain personal data
- Remaining context and links can identify the person even after the name is replaced.
Apply it to employee AI use
Bring your actual data path.
Aona can help teams evaluate sensitive-input policies on supported employee AI paths.
It does not choose a lawful basis, validate consent, make the Article 9 decision or guarantee anonymisation.
Compare the two invented adjustment-request prompts and record the policy result on the chosen application and input path.
Review your use caseFAQ
Questions for this decision
Can we rely on legitimate interests for special-category data?
Does every photograph count as special-category biometric data?
Does an employee consent checkbox settle the issue?
Are criminal-conviction records covered by the same rule?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- EU GDPR: Regulation (EU) 2016/679
Articles 5, 6, 9, 10, 12, 17, 19, 28, 32, 35 and 36 establish the relevant processing, rights, processor and risk-assessment requirements.
law · checked 2026-09-21